跳转到主内容

删除计算机帐户后、为什么Kerberos身份验证有效?

Views:
2
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
nas
Last Updated:

适用场景

  • ONTAP 9
  • CIFS/SMB
  • Kerberos

问题解答

  • Kerberos身份验证基于KDC (通常是域控制器)授予的票证、此票证将缓存在客户端、直到到期为止。
  • 当计算机帐户被禁用甚至被删除时、客户端将使用已授予的服务单、直到其到期、而不会检查KDC (如果计算机帐户有效或存在)。
    示例: 由于已与ONTAP共享现有服务单、即使权限被撤销、已授予的CIFS会话仍将继续工作。
  • 这是预期行为。

追加信息

其他信息文本

 

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.